CVE-2020-25576Critical· 9.8▾ MidnightAn issue was discovered in the rand_core crate before 0.4.2 for Rust. Casting of byte slices to integer slices mishandles alignment constraints.
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 53.9 · likelihood 0.3 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 20.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
1.6%
An issue was discovered in the rand_core crate before 0.4.2 for Rust. Casting of byte slices to integer slices mishandles alignment constraints.
rand < 0.4.2Upgrade past the affected range:
rand 0.4.2Connected by shared product, vendor, weakness, or advisory.
RUSTSEC-2026-0097NoneRand is unsound with a custom logger using `rand::rng()`
CVE-2026-50278Medium· 6.5iccDEV provides a set of libraries and tools for working with ICC color management profiles
CVE-2026-20249High· 8.6A vulnerability in the certification authentication feature of Internet Key Exchange version 2 (IKEv2) for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software coul…
CVE-2026-86348Medium· 4.3Mattermost versions <=11.9 11.0.9 11.4.8 11.7.7 10.22.11.0 fail to recover from handler panics, which allows an authenticated user to crash the plugin via a post-action request with an unexpected field type.
CVE-2026-87546Medium· 4.3Incorrect type conversion or cast in Safebrowsing in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted file
CVE-2026-28609High· 8.8In read of MatroskaExtractor.cpp, there is a possible out-of-bounds write due to improper casting